Linux kernel是美国Linux基金会开源的一款操作系统内核。 Linux kernel 2.6.34版本存在安全漏洞,该漏洞源于nexio_read_data()函数从设备中断数据包中提取data_len和x_len字段,且未对从URB缓冲区读取的数据长度进行有效限制,导致设备可伪造长度值,造成约64 KiB越界读取,相邻内核内存内容可能以ABS_X/ABS_Y事件泄露至用户空间,进一步读取可能导致内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 5197424cdcccd2b0b1922babb93969b2515c43ce< 45c829e5eb3b974282bae50b7cca2cc891f74f0b |
affected |
5197424cdcccd2b0b1922babb93969b2515c43ce< e7cdcb266ba06d8480809b78ab8bb2bf8ff51ccb |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< 95f47331dfde243f93e679ce70bd0c24b37c683d |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< d883312061ccde8c536595998aaf687ec070077c |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< 103d2de9f505f56da173e43f12dba62f92620278 |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< 0ca809ea8e0355299266c46e5f1755040aa8dcf3 |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< 7585b6aa55d8ac85ad22f522e1059f93507727b6 |
affected | ||
5197424cdcccd2b0b1922babb93969b2515c43ce< 2905281cbda52ec9df540113b35b835feb5fafd3 |
affected | ||
| … +10 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63795 | 10.0 CRITICAL | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-63887 | 9.8 CRITICAL | scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf |
| CVE-2026-63994 | 9.8 CRITICAL | tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() |
| CVE-2026-64035 | 9.8 CRITICAL | igc: set tx buffer type for SMD frames |
| CVE-2026-64142 | 9.8 CRITICAL | ksmbd: close durable scavenger races against m_fp_list lookups |
| CVE-2026-63993 | 9.8 CRITICAL | vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() |
| CVE-2026-53399 | 9.8 CRITICAL | nfsd: release layout stid on setlease failure |
| CVE-2026-53398 | 9.8 CRITICAL | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-63825 | 9.8 CRITICAL | gcov: use atomic counter updates to fix concurrent access crashes |
| CVE-2026-64025 | 9.8 CRITICAL | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-64033 | 9.8 CRITICAL | RDMA/rtrs: Fix use-after-free in path file creation cleanup |
| CVE-2026-63886 | 9.8 CRITICAL | scsi: target: iscsi: Validate CHAP_R length before base64 decode |
| CVE-2026-64125 | 9.8 CRITICAL | net: bcmgenet: keep RBUF EEE/PM disabled |
| CVE-2026-64091 | 9.8 CRITICAL | batman-adv: tt: fix TOCTOU race for reported vlans |
| CVE-2026-63808 | 9.8 CRITICAL | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-63978 | 9.8 CRITICAL | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-63979 | 9.8 CRITICAL | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-64132 | 9.8 CRITICAL | ipv6: ioam: refresh hdr pointer before ioam6_event() |
| CVE-2026-64136 | 9.8 CRITICAL | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() |
| CVE-2026-63800 | 9.8 CRITICAL | pNFS: Fix use-after-free in pnfs_update_layout() |
Showing top 20 of 429 CVEs. View all on vendor page → →
No comments yet